Unbounded Memory Copy Vulnerability in PX4 Autopilot Flight Control Software
CVE-2026-32707
5.2MEDIUM
What is CVE-2026-32707?
The PX4 Autopilot flight control software has been identified with a memory corruption vulnerability due to an unbounded memcpy in the tattu_can multi-frame assembly loop. This issue affects versions prior to 1.17.0-rc2, enabling an attacker with CAN-injection capabilities to exploit this flaw. When crafted CAN frames are processed, it may lead to a stack memory overwrite, potentially resulting in a denial of service (DoS) and causing unforeseen crashes. It is highly recommended to update to version 1.17.0-rc2 or later to mitigate these risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PX4-Autopilot < 1.17.0-rc2
